Field notes · 17 February 2026

Control narratives that survive a director’s second question

Why fintech control descriptions fail under follow-up — and how to write narratives that match ledger practice before audits begin.

Person typing on a laptop while reviewing documents
A control narrative should name people, systems of record, and evidence — not aspirations.

Control narratives often read like aspirations: “User funds are segregated.” Directors and reviewers then ask the second question: segregated where, by whom, and with what monthly evidence?

A narrative that survives scrutiny names the accounts, the approvers, the frequency of reconciliation, and the artifact that proves the step happened. In audits for fintech, the artifact usually sits in a reconciliation binder, a bank letter, or a signed month-end checklist — not in a slide deck.

Avoid verbs that hide ownership. “Is monitored” invites the question of who monitors. “The finance lead compares the partner settlement total to the clearing account each business day and initials the reconciliation sheet” answers that question before it is asked.

We also encourage teams to date their narratives. Controls change when products launch or partners switch. An undated page from two licence drafts ago creates unnecessary friction in a pre-licence readiness review.

If you are preparing for White Pine’s readiness engagement, send the narratives you would actually hand a director — not a polished rewrite created only for outsiders. Honest drafts produce better gap lists.